Amazon Quietly Closes Security Hole After Journalist’s Devastating Hack
wired.com
wired.com
This is only a story because of Apple's of operational decisions. The information required to game their system could have come from a myriad of sources other than Amazon.
I know a guy that's a huge amazon seller and he says there are Amazon sellers often with upwards of $100,000 in their accounts on Amazon before pulling the cash out. If someone were able to gain access to a seller account (I'm not sure if this 'exploit' would have worked for a seller account or not), that could have been quite financially painful for some people.
I could walk up to an ATM behind someone and get the last 4 of their card all day long. It is printed on every single receipt you've ever gotten.
Anyway, you are wrong about Amazon being FDIC insured like normal banks. They can potentially insure you up to $100,000 via pooled accounts stored at FDIC banks. Amazon payment accounts themselves are not FDIC insured. So you can imagine how much fun it would be to get your money back as compared with a real bank.
As for storing $250,000 in the same bank, I am highly confused what a company otherwise does. I have a company, and while I don't actually own a lot of the money that I hold on to (it is almost entirely held liabilities for things like sales tax or vendors), at any given moment I am certainly holding more than $250,000.
Do you then contend that I should be having numerous bank accounts to hold this money? I can't invest it, as I need to have the money to pay the aforementioned liabilities at the end of pay periods that are too short to move money in and out of investments. (Note: I also do not believe my business is somehow crazy-weird.)
The absence of any sort of backup measures at Apple allowed a lost password access followed immediately by the wiping of three devices to go entirely unnoticed. It's not just the lack of rigor Apple implemented in the password recovery process, it's that that is all there was. Apple didn't defend in depth at all - there was just one call center employee between the black hat and mischief.
The thing is that Amazon's previous risk assessment was probably about what sort of harm could be done directly with the info provided. Now they are worried about what can be done through other providers that will bring them bad press.
The concrete problem the journalist experienced was mostly due to the level of security Apple chose, sure, but that’s only because the hacker chose not to exploit being able to access the Amazon account.
The problem with Amazon is not that they give out the last four digits of the credit card. The problem is that you can access anyone’s account.
Amazon: You can access the account. And like order Hello kitty plush toys in someone else's name.
Apple: You can access the account. Then possibly remote-wipe all data belonging to whoever owns that account, data which may or may not be recoverable.
There is a slight difference. Apple has a much bigger responsibility here. Amazon is just responding because this is bad press, and they are basically covering Apple's ass here.
Apple, as per usual, has a shitty security record. Unless Microsoft, they haven't learned that security is a something which has to be baked in at the root of your products and services. It needs to be there from the start and isn't something which can be tacked on later.
For a short time, Apple was ahead of Microsoft in security because its OS was based on Unix-roots. Now they've built so many systems on top of that, and we can clearly see that Apple itself has no concept about security. Apart, ofcourse, for DRMed media and its own walled iOS-gardens.
The only security Apple cares about is its own. I wonder when their Microsoft-moment will come and they realize they have a responsibility towards their customers security wise as well.
I wasn’t comparing this hole to Apple’s security. I was merely pointing out that this is a big fucking deal. Because it is.
What’s wrong with you? Do you fear that Apple might not look so bad if you admit that Amazon also screwed up quite a bit? Are you so fanatical in your hate of Apple?
Apple’s security hole is the bigger deal here, certainly, but Amazon’s is also a big fucking deal.
I remember searching for people with an @hotmail.com account in ICQ just to see if I could enter to see their emails. This was like, 15 years ago IIRC.
Or you could just use them alongside other verification steps.
Edit: I guess that may not be sufficient to identify you, but it could verify that you are the account holder for other services.
You really think they are going to be happy about sitting around typing that in on their phone hoping they don't make a mistake ?
With standard numbers, you could use any touch tone phone.
At some point, there has to be a way to get back into your account. Probably, going through slow and hard to hack methods like the postal system.
EDIT: OK, I can disable remote wipe entirely by disabling 'find my mac'.
Now the reason why the attacker was able to remote wipe is because he had the iCloud username and the newly generated password.
Press releases and public announcements are how a company communicates. If a company changes something without communicating, they changed something quietly.
I’m not really understanding what point you are trying to make. What is there to misunderstand about that “quietly”?